Hello all,
I need some help on the following, i am trying to stop access of all websites (browser) from the remote office using the fortigate 30E. The users should only have access to the mail server and some applications which are on the internet (example teamviewer and all), i am using a public dns such as google.
The simplest will be set to allow only ports to the mailserver and those internet applications, however since DNS is now blocked via policies, i am not able to reach by URLs, however by IPs it is ok .. This of course stops users from surfing and is the most ideal but is there any way to allow the DNS to work to resolve URLS but not allowing users to surf?
Thank you!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Welcome to the forums.
Simply do not create a policy allowing http/https traffic. No policy = no access. If you have the per defined 'any/any/all' policy enabled then create one before that which denies http/https traffic. Policies are executed from the top down so place before the global allow. You [should] know your network. You should remove any global allows and break down the traffic the way it is supposed to flow. Good security and laziness (or sloppiness) are exclusive concepts in fire-walling.
Hope that helps
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
If you want to allow Teamviewer you need to allow HTTPS. I would create a separate policy to allow HTTPS and apply an Application Control sensor to exempt Teamviewer (rough sketch, you know what I mean).
Hello all,
Thanks for the tips! i found out just a simple first rule of any to any and allowing only the dns service for that rule allows the url resolution to work perfectly. of coz the separate rules to block off http / https traffic will be in separate rules :)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.